OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
BID:36844
Info
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 36844 |
| Class: | Design Error |
| CVE: |
CVE-2009-3767 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Apr 13 2015 09:47PM |
| Credit: | Joe Orton |
| Vulnerable: |
VMWare ESX 4.1 VMWare ESX 4.0 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Redhat JBoss Enterprise Web Server for Windows 1.0 Redhat JBoss Enterprise Web Server for Solaris 1.0 Redhat JBoss Enterprise Web Server for RHEL 6 1.0 Redhat JBoss Enterprise Web Server for RHEL 5 Server 1.0 Redhat JBoss Enterprise Web Server for RHEL 4 ES 1.0 Redhat JBoss Enterprise Web Server for RHEL 4 AS 1.0 Redhat JBoss Enterprise Web Server EL4 0 Redhat JBoss Enterprise Web Server 5.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4.8.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.8.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Pardus Linux 2009 0 OpenLDAP OpenLDAP 2.4.3 OpenLDAP OpenLDAP 2.4.2 OpenLDAP OpenLDAP 2.4.1 OpenLDAP OpenLDAP 2.4 OpenLDAP OpenLDAP 2.3.41 OpenLDAP OpenLDAP 2.3.40 OpenLDAP OpenLDAP 2.3.39 OpenLDAP OpenLDAP 2.3.27 OpenLDAP OpenLDAP 2.3.25 OpenLDAP OpenLDAP 2.3.6 OpenLDAP OpenLDAP 2.2.29 OpenLDAP OpenLDAP 2.2.26 OpenLDAP OpenLDAP 2.2.15 OpenLDAP OpenLDAP 2.2.6 OpenLDAP OpenLDAP 2.1.30 OpenLDAP OpenLDAP 2.1.25 OpenLDAP OpenLDAP 2.1.22 OpenLDAP OpenLDAP 2.1.19 OpenLDAP OpenLDAP 2.1.18 OpenLDAP OpenLDAP 2.1.17 OpenLDAP OpenLDAP 2.1.16 OpenLDAP OpenLDAP 2.1.15 OpenLDAP OpenLDAP 2.1.14 OpenLDAP OpenLDAP 2.1.13 OpenLDAP OpenLDAP 2.1.12 OpenLDAP OpenLDAP 2.1.11 OpenLDAP OpenLDAP 2.1.10 OpenLDAP OpenLDAP 2.1.4 OpenLDAP OpenLDAP 2.1 .20 OpenLDAP OpenLDAP 2.0.27 OpenLDAP OpenLDAP 2.0.25 OpenLDAP OpenLDAP 2.0.23 OpenLDAP OpenLDAP 2.0.22 OpenLDAP OpenLDAP 2.0.21 OpenLDAP OpenLDAP 2.0.20 OpenLDAP OpenLDAP 2.0.19 OpenLDAP OpenLDAP 2.0.18 OpenLDAP OpenLDAP 2.0.17 OpenLDAP OpenLDAP 2.0.16 OpenLDAP OpenLDAP 2.0.15 OpenLDAP OpenLDAP 2.0.14 OpenLDAP OpenLDAP 2.0.13 OpenLDAP OpenLDAP 2.0.12 OpenLDAP OpenLDAP 2.0.11 -9 OpenLDAP OpenLDAP 2.0.11 -11S OpenLDAP OpenLDAP 2.0.11 -11 OpenLDAP OpenLDAP 2.0.11 OpenLDAP OpenLDAP 2.0.10 OpenLDAP OpenLDAP 2.0.9 OpenLDAP OpenLDAP 2.0.8 OpenLDAP OpenLDAP 2.0.7 OpenLDAP OpenLDAP 2.0.6 OpenLDAP OpenLDAP 2.0.5 OpenLDAP OpenLDAP 2.0.4 OpenLDAP OpenLDAP 2.0.3 OpenLDAP OpenLDAP 2.0.2 OpenLDAP OpenLDAP 2.0.1 OpenLDAP OpenLDAP 2.3.28-E1.0.0 OpenLDAP OpenLDAP 2.3.28-20061022 OpenLDAP OpenLDAP 2.3.28-2.20061022 OpenLDAP OpenLDAP 2.3.27-2.20061018 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IQ 5.1 Avaya IQ 5 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 |
| Not Vulnerable: |
Redhat JBoss Enterprise Web Server for Windows 1.0.2 Redhat JBoss Enterprise Web Server for Solaris 1.0.2 Redhat JBoss Enterprise Web Server for RHEL 6 1.0.2 Redhat JBoss Enterprise Web Server for RHEL 5 Server 1.0.2 Redhat JBoss Enterprise Web Server for RHEL 4 ES 1.0.2 Redhat JBoss Enterprise Web Server for RHEL 4 AS 1.0.2 |
Discussion
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
OpenLDAP is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
OpenLDAP is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
Attackers use man-in-the-middle attacks to exploit this issue.
Attackers use man-in-the-middle attacks to exploit this issue.
Solution / Fix
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
Mandriva Linux Mandrake 2008.0
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Mandriva Linux Mandrake 2009.0 x86_64
Debian Linux 5.0 mips
Debian Linux 5.0 sparc
Debian Linux 4.0 arm
Mandriva Linux Mandrake 2009.1 x86_64
Debian Linux 4.0 powerpc
MandrakeSoft Enterprise Server 5
Ubuntu Ubuntu Linux 6.06 LTS i386
Debian Linux 5.0 hppa
Debian Linux 4.0 sparc
Mandriva Linux Mandrake 2009.0
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
-
Debian ldap-utils_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4 .11-1+lenny1_alpha.deb -
Debian libldap-2.4-2-dbg_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2- dbg_2.4.11-1+lenny1_alpha.deb -
Debian libldap-2.4-2_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_ 2.4.11-1+lenny1_alpha.deb -
Debian libldap2-dev_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2 .4.11-1+lenny1_alpha.deb -
Debian slapd-dbg_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4. 11-1+lenny1_alpha.deb -
Debian slapd_2.4.11-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/o/openldap/slapd_2.4.11-1 +lenny1_alpha.deb
Mandriva Linux Mandrake 2008.0
-
Mandriva libldap2.3_0-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.3_0-devel-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.3_0-static-devel-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-clients-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-doc-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-servers-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-testprogs-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-tests-2.3.38-3.4mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 amd64
-
Debian ldap-utils_2.3.30-5+etch3_amd64.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/ldap-utils_ 2.3.30-5+etch3_amd64.deb -
Debian slapd_2.3.30-5+etch3_amd64.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/slapd_2.3.3 0-5+etch3_amd64.deb
Debian Linux 4.0 ia-32
-
Debian ldap-utils_2.3.30-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/ldap-utils_ 2.3.30-5+etch3_i386.deb -
Debian libldap-2.3-0_2.3.30-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/libldap-2.3 -0_2.3.30-5+etch3_i386.deb -
Debian slapd_2.3.30-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/slapd_2.3.3 0-5+etch3_i386.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva lib64ldap2.4_2-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64ldap2.4_2-devel-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64ldap2.4_2-static-devel-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-clients-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-doc-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-servers-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-testprogs-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-tests-2.4.11-3.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 mips
-
Debian ldap-utils_2.4.11-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4 .11-1+lenny1_mips.deb -
Debian libldap-2.4-2-dbg_2.4.11-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2- dbg_2.4.11-1+lenny1_mips.deb -
Debian libldap-2.4-2_2.4.11-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_ 2.4.11-1+lenny1_mips.deb -
Debian libldap2-dev_2.4.11-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2 .4.11-1+lenny1_mips.deb -
Debian slapd-dbg_2.4.11-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4. 11-1+lenny1_mips.deb
Debian Linux 5.0 sparc
-
Debian libldap-2.4-2-dbg_2.4.11-1+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2- dbg_2.4.11-1+lenny1_sparc.deb -
Debian slapd-dbg_2.4.11-1+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4. 11-1+lenny1_sparc.deb
Debian Linux 4.0 arm
-
Debian ldap-utils_2.3.30-5+etch3_arm.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/ldap-utils_ 2.3.30-5+etch3_arm.deb -
Debian slapd_2.3.30-5+etch3_arm.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/slapd_2.3.3 0-5+etch3_arm.deb
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva lib64ldap2.4_2-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64ldap2.4_2-devel-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64ldap2.4_2-static-devel-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-clients-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-doc-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-servers-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-testprogs-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-tests-2.4.16-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 powerpc
-
Debian libldap-2.3-0_2.3.30-5+etch3_powerpc.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/libldap-2.3 -0_2.3.30-5+etch3_powerpc.deb
MandrakeSoft Enterprise Server 5
-
Mandriva libldap2.4_2-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.4_2-devel-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.4_2-static-devel-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-clients-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-doc-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-servers-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-testprogs-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-tests-2.4.11-3.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu ldap-utils_2.2.26-5ubuntu2.9_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/ldap-utils_2 .2.26-5ubuntu2.9_i386.deb -
Ubuntu libldap-2.2-7_2.2.26-5ubuntu2.9_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/libldap-2.2- 7_2.2.26-5ubuntu2.9_i386.deb -
Ubuntu slapd_2.2.26-5ubuntu2.9_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openldap2.2/slapd_2.2.26 -5ubuntu2.9_i386.deb
Debian Linux 5.0 hppa
-
Debian ldap-utils_2.4.11-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4 .11-1+lenny1_hppa.deb -
Debian libldap-2.4-2_2.4.11-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_ 2.4.11-1+lenny1_hppa.deb -
Debian libldap2-dev_2.4.11-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2 .4.11-1+lenny1_hppa.deb -
Debian slapd-dbg_2.4.11-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4. 11-1+lenny1_hppa.deb
Debian Linux 4.0 sparc
-
Debian ldap-utils_2.3.30-5+etch3_sparc.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/ldap-utils_ 2.3.30-5+etch3_sparc.deb -
Debian slapd_2.3.30-5+etch3_sparc.deb
http://security.debian.org/pool/updates/main/o/openldap2.3/slapd_2.3.3 0-5+etch3_sparc.deb
Mandriva Linux Mandrake 2009.0
-
Mandriva libldap2.4_2-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.4_2-devel-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libldap2.4_2-static-devel-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-clients-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-doc-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-servers-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-testprogs-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva openldap-tests-2.4.11-3.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
References
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
References:
References:
- [oss-security] More CVE-2009-2408 like issues (Tomas Hoger)
- Avaya Security Advisory ASA-2010-117 (Avaya)
- Diff for /libraries/libldap/tls_g.c between version 1.13 and 1.14 (OpenLDAP)
- Diff for /libraries/libldap/tls_m.c between version 1.8 and 1.11 (OpenLDAP)
- Diff for /libraries/libldap/tls_o.c between version 1.8 and 1.11 (OpenLDAP)
- VMSA-2010-0015 VMware ESX third party updates for Service Console (VMWare)
- RHSA-2010:0543-1 Moderate: openldap security update (Red Hat)